Thanks to ahodes for the heads up :)
UPDATED: MS02-028 Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise
Title: Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise (Q321599)
Released: 12 June 2002
Revised: 01 July 2002 (version 2.0)
Software: Internet Information Server
Impact: Run Code of Attacker's Choice
Max Risk: Critical
Bulletin: MS02-028
Reason for Revision:
====================
On June 12, 2002, Microsoft released the original version of this bulletin. On July 1, 2002, the bulletin was updated to revise the severity rating. Specifically, Microsoft has increased the severity rating of this issue to "critical ." The revision is in response to a significant change in the threat environment due to an increased focus on chunked encoding vulnerabilities in general, and the discovery of hostile code attempting to exploit similar vulnerabilities on other platforms. Customers who have already disabled HTR or applied this patch need not take any action. Customers who have not disabled HTR should do so as soon as possible. Alternately, customers who cannot disable HTR should apply the patch immediately.
View: MS02-028
Download locations for this patch:
Download: Microsoft IIS 4.0
Download: Microsoft IIS 5.0